Skip to main content
KU

Kumu

GDPR evidence

kumu.ioLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Kumu and GDPR

CertReports found no public GDPR evidence for Kumu as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: EU-US Certification, SW-US Certification, UK Extension Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
16 May 2017
Expires or valid through
22 Oct 2026
Scope
Kumu may collect non-personally-identifiable information of the sort that web browsers and servers typically make available, such as the browser type, language preference, referring site, and the date and time of each visitor request. Kumu’s purpose in collecting non-personally identifying information is to better understand how Kumu’s visitors use its website and to monitor and improve our Website and Services. From time to time, we may release non-personally-identifying information in the aggregate, e.g., by publishing a report on trends in the usage of its website. When a user registers for Kumu, we collect personal information including name, username, email, account password, account name and date of registration. We also collect potentially personally-identifying information like Internet Protocol (IP) addresses, information about your computer, geographic location, and other standard web log information. We do not disclose personally-identifying information other than as described below. Visitors can always refuse to supply personally-identifying information, with the caveat that it may prevent them from engaging in certain website-related activities. We may collect statistics about the behavior of visitors to the Website. For instance, we may monitor the most popular public accounts and display this information publicly or provide it to others. However, Kumu will not disclose personally-identifying information other than as described below. A cookie is a string of information that a website stores on a visitor’s computer, and that the visitor’s browser provides to the website each time the visitor returns. Kumu uses cookies to help Kumu identify and track visitors, their usage of Kumu website, and their website access preferences. Kumu visitors who do not wish to have cookies placed on their computers should set their browsers to refuse cookies before using the Website, with the drawback that certain features of the Website may not function properly without the aid of cookies. When paying for an account subscription, Kumu uses a third party payment processor, Stripe, to assist in processing your personally identifiable payment information. We do not receive or store credit card information into our servers. Kumu discloses potentially personally-identifying and personally-identifying information only to those of its employees, contractors and affiliated organizations that (i) need to know that information in order to process it on Kumu’s behalf or to provide services available at the Website, and (ii) that have agreed not to disclose it to others. Some of those employees, contractors and affiliated organizations may be located outside of your home country; by using Kumu, you consent to the transfer of such information to them. Kumu will not rent or sell potentially personally-identifying and personally-identifying information to anyone. Other than to its employees, contractors and affiliated organizations, as described above, Kumu discloses potentially personally-identifying and personally-identifying information only in response to a subpoena, court order or other governmental request, or when Kumu believes in good faith that disclosure is reasonably necessary to protect the property or rights of Kumu, third parties or the public at large.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Kumu Inc.: Active: EU-US Certification, SW-US Certification, UK Extension Certification
Live pagesha256 45390ff70f
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Kumu GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.

No same-category vendor has GDPR evidence in the index yet.